Introduction and Initial Configuration Flashcards
Why would anyone use a virtual Fortigate?
In large-scale networks that change rapidly and may have many tenants, equivalent processing power and distribution may be achievable using larger amounts of cheaper, general purpose hardware.
Why do virtual Fortigates have the same features as physical Fortigates, expect for hardware acceleration?
First, the hardware abstraction layer software for hypervisors is made by other vendors, not Fortinet.. Second, the purpose of generic virtual CPUs is to abstract the hardware details of hypervisors. That way, all VM guest OSs can run on a common platform, no matter the different hardware. Unlike vCPUs or vGPUs that use generic, non-optimal RAM and vCPUs for abstraction, SPU chips are optimized circuits. Therefore, a virtualized ASIC ship would not yield the same performance benefits as a physical SPU chip.
FOrtigate VMX and Fortigate Connector for Cisco ACI are what?
They are specialized versions of FortiOS and an API that allows you to orchestrate rapid network changes through standards, such as OpenStack for software-defined networking (SDN).
Fortigate VM is deployed as what?
A guest VM on the hypervisor.
Fortigate VMX is deployed where?
Inside a hypervisor’s virtual networks, between guest VMs.
What is Fortigate Connector for Cisco ACI?
It allows ACI to deploy physical or virtual Fortigate VMs for north-south traffic.
What are Fortigate VMs’ specifications?
Licenses: Max 1/2/3/4/8 vCPU
Hypervisor: VMWare, Hyper-V, KVM, Citrix Xen Server, Open Source Xen, Azure, Amazon AWS BYOL & on-demand
Memory: Max 1/2/4/8/12 GB
NICs: 2-4 virtual
Storage capacity: 40GB+
What are SPUs?
(security processing units) which are used for hardware acceleration. They include NPx and CPx processors.
What is NTurbo?
NTurbo offloads firewall sessions that include flow-based security profiles to NP6 or NP7 network processors. Without NTurbo, all firewall sessions that include flow-based security profiles are processed by the Fortigate CPU.
What are CPs?
Content Processors. These processors accelerate a wide range of important security processes such as virus scanning, attack detection, encryption and decryption. Most Fortigates include these.
What are SPs?
Security processors. They function the same as CPs, but instead accelerate processing of IPS.
What are NPs?
Network processors. They offload processing of high volume network traffic.
What more information can you provide about Fortinet’s CPs?
CP9 is not bound to an internet, thus works outside the direct flow of traffic. It provides high-speed cryptography and content inspection services.
This allows administrators to deploy advanced security on-demand without impacting network functionality.
What is NAT Mode?
Packets are routed based on layer 3. Each logical network interface has an IP address and Fortigate determines the outgoing or egress interface based on the destination IP and entries in routing tables.
What is transparent mode?
Packets are forwarded at Layer 2, like a switch. The device in transparent mode has an IP address used for management traffic.